CVE-2014-3590: CSRF
Published Jan 2, 2020
·Updated
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.
Affected Software
2 affected components
debian
redhat Satellite=6.0
Event History
Jan 2, 2020
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-3590?
The severity of CVE-2014-3590 is medium with a CVSS score of 6.5.
2
How does CVE-2014-3590 affect Foreman?
Versions of Foreman as shipped with Red Hat Satellite 6 are affected by CVE-2014-3590.
3
What is the impact of CVE-2014-3590?
An attacker can log out a user by having them view specially crafted content.
4
How can I fix the vulnerability in Red Hat Satellite 6?
There is no official fix available for CVE-2014-3590 in Red Hat Satellite 6 at this time. It is recommended to stay updated with the latest security advisories.
5
Is Debian affected by CVE-2014-3590?
Debian is not affected by CVE-2014-3590.